Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cuppacms cuppacms 1.0 vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-47990
SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows malicious users to run arbitrary SQL commands via the table parameter.
Cuppacms Cuppacms 1.0
7.5
CVSSv3
CVE-2022-25401
The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.
Cuppacms Cuppacms 1.0
9.8
CVSSv3
CVE-2022-25495
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows malicious users to upload arbitrary files and execute arbitrary code via a crafted PHP file.
Cuppacms Cuppacms 1.0
9.8
CVSSv3
CVE-2022-25498
CuppaCMS v1.0 exists to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
Cuppacms Cuppacms 1.0
9.8
CVSSv3
CVE-2022-27984
CuppaCMS v1.0 exists to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.
Cuppacms Cuppacms 1.0
9.8
CVSSv3
CVE-2022-27985
CuppaCMS v1.0 exists to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.
Cuppacms Cuppacms 1.0
8.8
CVSSv3
CVE-2022-37190
CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.
Cuppacms Cuppacms 1.0
7.5
CVSSv3
CVE-2022-24265
Cuppa CMS v1.0 exists to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.
Cuppacms Cuppacms 1.0
9.8
CVSSv3
CVE-2023-39681
Cuppa CMS v1.0 exists to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.
Cuppacms Cuppacms 1.0
8.1
CVSSv3
CVE-2022-24647
Cuppa CMS v1.0 exists to contain an arbitrary file deletion vulnerability via the unlink() function.
Cuppacms Cuppacms 1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »